๐Ÿ” CVE Alert

CVE-2026-75823

UNKNOWN 0.0

WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.

Vendor unknown
Product user frontend
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown user frontend

Be the first to know when new unknown vulnerabilities affecting unknown user frontend are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / User Frontend
3.5.29 < 4.3.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4a385690-3471-4604-aa2a-e120bb31ca53/

Credits

Murad Akhmedov WPScan